Inspiration

• Retail investors in India routinely hold portfolios scattered across multiple brokers and depositories with no single view of what they actually own. On top of that, alternate instruments like REITs and InvITs are widely mis-sold or misunderstood — investors don't grasp lock-in periods, liquidity risk, or suitability mismatches until it's too late. SEBI has repeatedly flagged this as a real investor-protection gap. Every existing portfolio tool we looked at made this worse by reducing risk to a single opaque number with no explanation attached. We wanted to build something that did the opposite: surface the same risks, but explain why they matter in plain language a non-expert investor can actually act on.

What it does

• VestIQ aggregates a fragmented portfolio — equities, bonds, REITs, and InvITs across any broker or depository — into one unified dashboard, and replaces black-box risk scores with causal-chain explanations (e.g. "40% in one REIT → rate-sensitive asset class → -15% estimated per +1% rate move"). On top of that core engine, it includes a Mis-Selling Red Flag Detector, a What-If simulator for testing hypothetical portfolio changes, a Shock Sandbox for stress-testing against rate/market moves, Peer Benchmarking, a Retrospective Simulator, and a proactive Portfolio Guardian that flags relevant market news against a user's actual holdings. Role-based access control spans Investor, Broker/RM, Compliance Officer, and Admin roles, each scoped differently — and a DPDP Act-aligned data export and deletion flow gives users direct control over their own data.

How we built it

• The frontend is React, TypeScript, and Vite with Tailwind CSS, using Recharts and Chart.js for visualizations. The backend is a Node.js/Express layer sitting in front of Supabase (Postgres, Auth, and Row Level Security), with CAS statement parsing handled by a text-extraction pipeline plus an LLM step that turns messy extracted text into structured holdings data. We leaned heavily on AI-assisted development throughout — not just for writing code, but for running structured self-audits of our own build, which is how several of the real issues below actually got caught before submission rather than during judging.

Challenges we ran into

• The hardest problems weren't features, they were trust boundaries. Early on, the Health Score was calculating entirely client-side, meaning a technically capable user could manipulate their own score in dev tools — we caught this and moved the authoritative calculation server-side. We found a data-isolation bug where a brand-new account could see another session's demo portfolio data, traced it to a shared persistence path, and fixed it with proper per-user scoping and RLS policies. We also had to have an honest conversation with ourselves about a "PAN Tokenization" claim in our own compliance copy — it turned out we were only masking PANs for display, not tokenizing them in the backend, so we corrected the copy rather than leave an overstated security claim in front of judges. Several of these were only caught because we deliberately asked our own build to audit itself and report gaps plainly instead of assuming everything worked.

Accomplishments that we're proud of

• Building an explainability layer that isn't cosmetic — every score, flag, and suggestion traces back to a structured, specific reason, not just a number with a color. Making the RBAC model an actual compliance mechanism (aggregate-first views, audit-logged PII access, server-enforced role boundaries) rather than just a login gate. And catching real security gaps — client-side score manipulation, cross-account data leakage, an unimplemented tokenization claim — before they became a problem in front of judges, instead of after.

What we learned

• That the most technically impressive parts of a system like this — the parsing, the scoring, the dashboards — are rarely what determines whether it's trustworthy. What determines that is what the system refuses to assume, how honestly it labels a real feature versus an aspirational one, and how rigorously you verify a fix actually works rather than trusting a confident-sounding report. We came out of this build far more disciplined about that distinction than we expected to going in.

What's next for VestIQ

• Full production-grade authentication (secure password change, leaked-password protection, mandatory email verification) • A structured, native mobile app — not just a responsive web view — with offline-friendly CAS upload and push alerts • Real PAN tokenization via a dedicated vault/KMS integration, replacing today's API-boundary masking • Integration with RBI's consent-based Account Aggregator framework, moving beyond manual CAS upload to verified, real-time data • Multilingual explainability (Hindi, Tamil, and other Indic languages) • Deeper broker and compliance workflows, plus tax-impact awareness on suggested trades

Share this project:

Updates

Submission history